Security
The 103 checks in the “Security” category of a SQL Server audit: what each one verifies, its severity and the versions covered.
- Checks in this category
- 103
- Weight in the score
- 20
- Breakdown by severity
- 3 critical · 39 high · 30 medium · 6 low · 25 info
Checks in this category
SEC001SA Account Enabled
CriticalThe SA (System Administrator) account should be disabled to prevent brute force attacks
Versions : 2012-2025
SEC011xp_cmdshell Enabled
Criticalxp_cmdshell allows OS command execution and should be disabled
Versions : 2012-2025
SEC015Blank Password Logins
CriticalDetects SQL logins with blank passwords
Versions : 2012-2025
AUD001SQL Audit enabled and running
HighChecks that at least one server audit exists and is in STARTED state (a defined but stopped audit records nothing).
Versions : 2012-2025
AUD002Audit action groups cover security events
HighChecks that the enabled server audit specification covers key groups: successful/failed logins, role membership changes, permission and audit changes.
Versions : 2012-2025
AUD004Audit destination off system drive
HighChecks that the audit files are not written to the system drive nor to the default data volume, where they are exposed to saturation, deletion or tampering. It compares the drive letter only: file access rights are not inspected. An instance with no file audit at all has nothing to report here — AUD001 is the check that detects a missing audit.
Versions : 2012-2025
PERM001CONTROL SERVER granted to logins
HighChecks that no login holds the CONTROL SERVER permission, which is equivalent to the sysadmin role.
Versions : 2012-2025
PERM004High-impact fixed server roles minimal
HighChecks that securityadmin, serveradmin, processadmin, setupadmin, diskadmin, dbcreator and bulkadmin have minimal membership.
Versions : 2012-2025
PERM005High-impact fixed DB roles minimal
HighCounts members of db_securityadmin and db_accessadmin (excluding dbo) across all databases.
Versions : 2012-2025
PERM006db_owner not over-assigned
HighDetects databases where principals other than dbo are members of db_owner (full control of the database).
Versions : 2012-2025
PERM007ALTER on principals minimal
HighCounts principals holding ALTER ANY USER / ALTER ANY ROLE / ALTER on roles, which are privilege-escalation vectors.
Versions : 2012-2025
PERM011EXECUTE on registry XPs (xp_reg*) to non-dbo
HighChecks that no principal other than dbo has EXECUTE on registry extended procedures (xp_regread, xp_regwrite, ...).
Versions : 2012-2025
PERM012EXECUTE on xp_cmdshell to non-dbo
HighDetects EXECUTE grants on xp_cmdshell to principals other than dbo, exposing OS command execution.
Versions : 2012-2025
PERM019dbo SID consistent (DB vs server)
HighDetects databases whose owner_sid matches no server login (orphaned or ambiguous dbo mapping).
Versions : 2012-2025
POST002No user-defined CLR assemblies
HighDetects user-defined CLR assemblies (sys.assemblies is_user_defined), which expand the in-engine attack surface.
Versions : 2012-2025
POST003Trusted assemblies tracked
HighChecks sys.trusted_assemblies entries, which bypass CLR strict security and must all be inventoried and justified.
Versions : 2017-2025
POST004Engine on supported major version
HighChecks that the engine major version is still supported by Microsoft (EOL versions no longer receive security fixes).
Versions : 2012-2025
SEC002Password Policy
HighCounts the active SQL logins — excluding "sa" and the internal accounts — whose CHECK_POLICY is off (complexity and lockout) and those whose CHECK_EXPIRATION is off (renewal). The two options are independent: a missing CHECK_POLICY fails the check, a missing expiration alone raises a warning. The severity rises to critical when a login without CHECK_POLICY is a member of sysadmin.
Versions : 2012-2025
SEC004Sysadmin Members
HighCounts the members of the sysadmin role: SQL logins, Windows logins and Windows groups. Compliant up to 5 members, warning from 6 to 10, failure beyond. A Windows group counts as a single member, whatever the number of people it contains.
Versions : 2012-2025
SEC012Service Accounts
HighSQL services should not run under LocalSystem
Versions : 2012-2025
SEC013TRUSTWORTHY Databases
HighChecks if user databases have the TRUSTWORTHY flag enabled, which allows privilege escalation
Versions : 2012-2025
SEC014Cross-DB Ownership Chaining
HighChecks if cross-database ownership chaining is enabled at the server level
Versions : 2012-2025
SEC019Server-level and logon triggers
HighInventories server-level triggers, including LOGON triggers, and inspects their body for privileged calls. A LOGON trigger runs on every connection under the engine service account.
Versions : 2012-2025
SEC021Server credentials and SQL Agent proxies
HighInventories server credentials and SQL Agent proxies and checks who they are granted to. A proxy allows running code on the operating system under the Windows identity of the attached credential.
Versions : 2012-2025
SEC022External REST endpoint invocation enabled
HighChecks server option 'external rest endpoint enabled' (new in SQL Server 2025, default 0). When ON it enables sp_invoke_external_rest_endpoint, allowing outbound HTTPS from the engine to arbitrary endpoints (data-egress / SSRF surface).
Versions : 2025
SEC023External AI runtimes enabled (local ONNX runtime)
HighChecks server option 'external AI runtimes enabled' (new in SQL Server 2025, default 0). When ON it allows loading local ONNX models/libraries via the AI Runtime Host. Microsoft warns a malicious ONNX model can exfiltrate data or execute unauthorized code — native code-execution surface.
Versions : 2025
SEC026Holders of ALTER ANY SERVER AUDIT / CONTROL SERVER (audit tamper)
HighEnumerates every server principal able to create, alter or drop a SQL Server Audit and therefore silently disable audit logging: explicit grants of ALTER ANY SERVER AUDIT or CONTROL SERVER (which implies it), plus sysadmin members (implicit). A non-sysadmin holder is an unexpected SIEM blind spot.
Versions : 2012-2025
SEC027Database ownership / dbo mapping and db_owner least privilege (VA1143)
HighFlags least-privilege violations at the database level: user databases owned by a login other than sa (the owner login IS dbo, so an application login owning a database runs as dbo), members of the db_owner fixed role across databases, and the TRUSTWORTHY + owner-is-sysadmin combination — the classic db_owner→sysadmin privilege-escalation vector. Complements SEC004 (sysadmin count) without overlapping it.
Versions : 2012-2025
SEC028CLR assemblies with UNSAFE / EXTERNAL_ACCESS permission set (CIS 6.2)
HighScans every accessible database for user-defined CLR assemblies whose permission set is UNSAFE_ACCESS or EXTERNAL_ACCESS. UNSAFE assemblies can call native code and subvert the SQL Server / CLR security boundary (host compromise); EXTERNAL_ACCESS reaches files/network/registry. Microsoft system assemblies (is_user_defined=0) are excluded. Also reports the server 'clr enabled' and 'clr strict security' posture.
Versions : 2012-2025
SEC030Windows local groups used as SQL logins (CIS 3.10)
HighLists Windows-group logins (sys.server_principals, type G) whose prefix matches the machine name exactly (SERVERPROPERTY MachineName or, on a clustered instance, ComputerNamePhysicalNetBIOS). Local-group membership is managed by the local administrators of the host, outside any DBA control: whoever administers the machine can add themselves to the group and gain the corresponding SQL access. Complements SURF014 (BUILTIN groups, CIS 3.9); domain groups are out of scope.
Versions : 2012-2025
SEC031Admin role members (db_owner / db_ddladmin) in msdb (CIS 3.13)
HighLists members of the db_owner and db_ddladmin roles in the msdb system database other than dbo (msdb.sys.database_role_members). msdb hosts SQL Agent jobs, proxies, Database Mail and backup history: both roles allow creating or altering a job that will run as the Agent service account or a proxy — a privilege escalation that permission reviews miss because it lives in a system database.
Versions : 2012-2025
SEC032CHECK_EXPIRATION missing on sysadmin SQL logins (CIS 4.2)
HighLists the SQL-authenticated logins (sys.sql_logins) that are members of sysadmin, or that hold CONTROL SERVER, whose CHECK_EXPIRATION option is disabled: their password never expires. SEC002 reports the absence of CHECK_EXPIRATION on the active SQL logins other than "sa" (warning); here, "sa" and the disabled logins are on the contrary included. CIS 4.2 requires it strictly on the accounts that own the instance, because a sysadmin password set at installation stays valid for years and survives every departure. Disabled logins (typically "sa") are reported but only lower the verdict to a warning.
Versions : 2012-2025
SURF001Ad Hoc Distributed Queries off
HighChecks that 'Ad Hoc Distributed Queries' (OPENROWSET/OPENDATASOURCE) is disabled. When on, it widens the attack surface toward external sources.
Versions : 2012-2025
SURF004No auto-start stored procedures
HighLists procedures flagged ExecIsStartup that run automatically with high privilege when the service starts.
Versions : 2012-2025
SURF009FILESTREAM off when unused
HighChecks that FILESTREAM is disabled when no FILESTREAM data files exist, avoiding unnecessary surface area.
Versions : 2012-2025
SURF014BUILTIN\Administrators not a login
HighChecks that BUILTIN\Administrators is not a SQL login, otherwise every local administrator gains access to SQL Server.
Versions : 2012-2025
SURF015Features affecting security bundle off
HighComposite check of high-risk features (xp_cmdshell, OLE Automation, CLR, Ad Hoc Distributed Queries); all should be disabled.
Versions : 2012-2025
SURF016CLR strict security enabled
HighChecks that 'clr strict security' is enabled (2017+), treating SAFE/EXTERNAL_ACCESS assemblies as UNSAFE and requiring signing.
Versions : 2017-2025
TLS001Force Encryption (TDS) enabled
HighChecks that TDS protocol Force Encryption is enabled at the instance level so all client connections are encrypted in transit.
Versions : 2012-2025
TLS002Connections actually encrypted
HighInspects current TDS sessions (sys.dm_exec_connections) to detect connections still travelling in plaintext over the network.
Versions : 2012-2025
TLS005Mirroring/SSB endpoints use AES
HighChecks that database mirroring / Availability Group / Service Broker endpoints use AES encryption rather than RC4 or no encryption.
Versions : 2012-2025
TLS013TLS protocol posture and TDS 8.0 strict encryption
HighChecks that the obsolete TLS 1.0 and TLS 1.1 protocols are disabled at the SChannel level and, on SQL Server 2012 and 2014, that the engine supports TLS 1.2. From SQL Server 2025 on, also checks that TDS 8.0 strict encryption is enabled. The existing encryption checks indicate that connections are encrypted, never with which protocol.
Versions : 2012-2025
AUD003Failed-login auditing
MediumReads the AuditLevel registry value (login auditing to the SQL Server error log) and checks that failed logins are recorded. Passing: 2 (failed logins only, the shipped default and the CIS 5.3 requirement) and 3 (both failed and successful logins). Failing: 0 (no auditing) and 1 (successful logins only), which record no failed login.
Versions : 2012-2025
DATA001Sensitive-data classification applied
MediumChecks that sensitivity labels have been applied to columns (sys.sensitivity_classifications), supporting RGPD/PCI data inventory.
Versions : 2019-2025
PERM002Direct server permissions (outside roles)
MediumDetects server permissions granted directly to principals rather than through server roles (excluding CONNECT SQL / VIEW ANY DATABASE).
Versions : 2012-2025
PERM009User roles nested in fixed roles (server)
MediumDetects user-defined server roles that are members of fixed server roles, which obscures effective privileges.
Versions : 2012-2025
PERM013PUBLIC object/column grants
MediumCounts object- or column-level permissions granted to the PUBLIC role, i.e. to every user.
Versions : 2012-2025
PERM014PUBLIC server permissions minimized
MediumChecks that the PUBLIC server role keeps only its default permissions: VIEW ANY DATABASE at server level, and CONNECT on the built-in TSQL endpoints. Those CONNECT grants are excluded from the verdict, as they are present on every instance. CONNECT SQL is not granted to PUBLIC: it is granted login by login, when the login is created.
Versions : 2012-2025
PERM016User DBs with guest/public object grants
MediumCounts user databases where guest or public hold object-level permissions, widening the attack surface.
Versions : 2012-2025
PERM017model accessible by dbo only
MediumChecks that the model database (template for every new database) exposes no grants to principals other than dbo.
Versions : 2012-2025
PERM020Databases not owned by the built-in administrator account
MediumDetects the user databases whose owner is a named login — a personal account or a service account, the check does not tell them apart — instead of the built-in administrator account (SID 0x01).
Versions : 2012-2025
PERM021EXECUTE on dangerous XPs to non-dbo
MediumDetects EXECUTE grants to non-dbo on OLE Automation procedures (sp_OA*) and file-access XPs (xp_dirtree, xp_fileexist, ...).
Versions : 2012-2025
PERM022High-priv PUBLIC grants in system DBs
MediumDetects high-privilege object permissions (EXECUTE/ALTER/CONTROL/DML) granted to PUBLIC in master, msdb and model.
Versions : 2012-2025
PERM023User DB roles nested in fixed roles
MediumDetects, across all databases, user-defined database roles that are members of fixed database roles, hiding effective privileges.
Versions : 2012-2025
PERM024WITH GRANT OPTION delegation minimal
MediumDetects non-sysadmin logins holding server permissions granted WITH GRANT OPTION, letting them re-delegate privileges.
Versions : 2012-2025
POST005Cumulative Update applied
MediumChecks the patch level; an instance still on RTM with no Cumulative Update is potentially missing months or years of security fixes.
Versions : 2012-2025
SEC003Orphaned Users
MediumOrphaned users (without associated login) pose a security risk
Versions : 2012-2025
SEC005Guest Account Active
MediumThe Guest account should not have permissions in user databases
Versions : 2012-2025
SEC008Login Failures
MediumCounts the authentication failures (error 18456) of the last 24 hours in the error log, by error number: the count does not depend on the language of the server. Compliant up to 10 failures, warning beyond.
Versions : 2012-2025
SEC020Invalid Windows/AD logins
MediumFinds Windows logins and Active Directory groups that no longer resolve in the directory. These deleted accounts keep every server role and permission they were granted.
Versions : 2012-2025
SEC024External AI models registered (sys.external_models - data egress)
MediumInventories registered external AI models per database (sys.external_models). Each model targets an inference endpoint (Azure OpenAI/OpenAI/Ollama/ONNX Runtime) that may receive row data/embeddings — governance visibility and network-egress flagging.
Versions : 2025
SEC025Server-scoped database credentials allowed
MediumChecks server option 'allow server scoped db credentials' (new in SQL Server 2025, default 0). When ON, the host managed identity can be used as a database-level credential (e.g. Managed Identity auth for external models), broadening a privileged credential's scope.
Versions : 2025
SEC029Windows logins authenticating with NTLM instead of Kerberos (SPN posture)
MediumPoint-in-time snapshot of currently connected Windows-authenticated sessions that arrived over the network using NTLM rather than Kerberos, read from sys.dm_exec_connections.auth_scheme (stable enum, never localized). Remote Windows-auth NTLM indicates a missing or misconfigured Service Principal Name (SPN): no mutual authentication, exposure to NTLM relay, and constrained delegation is impossible. Local and shared-memory connections are excluded (forced to NTLM by design).
Versions : 2012-2025
SURF003Scan For Startup Procs off
MediumChecks that 'scan for startup procs' is disabled to prevent automatic execution of procedures at startup.
Versions : 2012-2025
SURF007Replication XPs off
MediumChecks that replication extended procedures are disabled when no replication is configured.
Versions : 2012-2025
SURF008User Options = 0
MediumChecks that 'user options' is 0, otherwise implicit SET options apply to every session and can silently alter application behaviour.
Versions : 2012-2025
SURF010External Scripts off when unused
MediumChecks that 'external scripts enabled' (Machine Learning Services R/Python) is off when unused, since it launches external runtimes.
Versions : 2016-2025
SURF011PolyBase export off when unused
MediumChecks that 'allow polybase export' is disabled, otherwise data can be written to external data sources.
Versions : 2016-2025
SURF017AUTO_CLOSE enabled on a contained database (CIS 2.15)
MediumLists contained databases (containment other than NONE) that have AUTO_CLOSE enabled (sys.databases). A contained database authenticates its own users, so even a failed login forces the engine to open the database in order to reject it. With AUTO_CLOSE, every attempt costs a full open/close cycle that an attacker can trigger in a loop over the network (denial of service). The control is considered met when there is no contained database; DBSET001 covers AUTO_CLOSE on every database.
Versions : 2012-2025
SURF018A login named 'sa' exists (CIS 2.16)
MediumVerifies that no server principal carries the name 'sa', whichever principal it is: the built-in account (sid 0x01) never renamed, or a login re-created under that name after the rename. Distinct from SEC001 (built-in account disabled, CIS 2.13) and SURF006 (built-in account renamed, CIS 2.14). 'sa' is the first name every brute-force and password-spray tool tries. A disabled 'sa' login downgrades the verdict to a warning.
Versions : 2012-2025
TLS004Extended Protection enabled
MediumChecks whether Extended Protection for Authentication (channel binding) is enabled to mitigate relay/MITM authentication attacks.
Versions : 2012-2025
TLS011Service account least-privilege
MediumChecks that the SQL Server engine does not run under a high-privilege built-in account (LocalSystem, Network Service, etc.).
Versions : 2012-2025
AUD008Error log retention (NumErrorLogs)
LowReads the NumErrorLogs registry value and checks that at least 12 recycled error logs are kept.
Versions : 2012-2025
DATA004UNMASK granted narrowly
LowChecks that no UNMASK permission is granted at the whole-database level (SQL 2022 supports column/schema-level UNMASK).
Versions : 2022-2025
PERM003Direct database permissions (outside roles)
LowCounts, across all databases, permissions granted directly to users instead of through database roles.
Versions : 2012-2025
PERM015GUEST securable permissions
LowDetects securable permissions (other than CONNECT) granted to the guest account in databases.
Versions : 2012-2025
SURF002Remote Access off
LowChecks that the legacy 'remote access' option (RPC sp_addserver) is disabled. This deprecated feature is no longer needed.
Versions : 2012-2025
SURF013Sample databases removed
LowDetects demo databases (AdventureWorks, WideWorldImporters, Northwind, pubs) that should not exist in production.
Versions : 2012-2025
AUD005Audit ON_FAILURE policy
InfoReports the ON_FAILURE policy of server audits. CONTINUE is accepted: the instance keeps running if the audit can no longer write. FAIL_OPERATION or SHUTDOWN are recommended for high-assurance environments. Informational check, no penalty.
Versions : 2012-2025
AUD006Audit retention / rollover configured
InfoDetects file audits with no bound (max_file_size = 0 and max_rollover_files = 0), which grow without limit.
Versions : 2012-2025
AUD007Database-level audit specifications
InfoChecks for enabled database audit specifications, which capture data access (SELECT/EXECUTE) not covered by server-level groups.
Versions : 2012-2025
AUD009Audit write waits not throttling
InfoExamines waits related to the audit/Extended Events pipeline to detect an audit target unable to keep up (event-loss risk).
Versions : 2012-2025
DATA002Likely-PII columns unclassified
InfoHeuristically (column name match: email, ssn, iban, dob, card, ...) finds likely-PII columns that carry no sensitivity label.
Versions : 2019-2025
DATA003Dynamic Data Masking on sensitive columns
InfoInventories columns protected by Dynamic Data Masking (sys.masked_columns).
Versions : 2016-2025
DATA005Row-Level Security policies present
InfoInventories enabled row-level security policies (sys.security_policies).
Versions : 2016-2025
DATA008Ledger enabled (integrity required)
InfoChecks whether the Ledger feature (cryptographic tamper-evidence) is enabled on databases requiring provable integrity.
Versions : 2022-2025
DATA009Ledger digest verification
InfoInformational reminder: Ledger tamper-evidence is only meaningful when digests are stored off-box immutably and verified regularly.
Versions : 2022-2025
PERM008IMPERSONATE grants inventory
InfoInventories IMPERSONATE permissions granted in databases, which let a principal act as another principal.
Versions : 2012-2025
PERM010Empty user-defined DB roles
InfoInventories user-defined database roles with no members (cleanup candidates).
Versions : 2012-2025
PERM018Application roles inventory
InfoInventories application roles (type 'A'), which carry a password, present in databases.
Versions : 2012-2025
POST001CLR strict security (inventory)
InfoReports the state of the "clr strict security" setting (SQL Server 2017 and later), which treats every assembly as UNSAFE unless it is signed. Inventory without a verdict: the verdict on this setting is carried by SURF016, which reads the same value — counting it twice would penalise a single setting twice.
Versions : 2017-2025
POST006Defender for SQL / Vulnerability Assessment
InfoDefender for SQL and SQL VA are Azure-managed capabilities; they cannot be evaluated from an on-prem T-SQL collector (informational note).
Versions : 2012-2025
SEC006Public Role Permissions
InfoInventory of the permissions held by the PUBLIC server role: server-level grants other than CONNECT SQL and VIEW ANY DATABASE, endpoint grants, and the total. Without a verdict: that one is carried by PERM014, so that a single grant is not counted twice.
Versions : 2012-2025
SEC007SQL vs Windows Auth
InfoReads the authentication mode of the instance (IsIntegratedSecurityOnly). Compliant in Windows-only mode; mixed mode is reported. The number of SQL logins is shown for information and is not part of any threshold: it is the server mode that decides whether those logins can be used.
Versions : 2012-2025
SEC009Database Owners
InfoDatabases should not be owned by user accounts
Versions : 2012-2025
SEC010TDE Encryption
InfoSensitive databases should use Transparent Data Encryption
Versions : 2012-2025
SEC016SQL Server Audit Configured
InfoChecks if SQL Server Audit is configured to trace security events
Versions : 2012-2025
SEC017High-Privilege Server Roles
InfoIdentifies logins that are members of high-privilege server roles (sysadmin, securityadmin, serveradmin)
Versions : 2012-2025
SEC018Linked Servers Using SA
InfoDetects linked servers whose mapping uses the SA account or an admin account
Versions : 2012-2025
SURF005Hide Instance enabled
InfoChecks that the instance is hidden from SQL Browser enumeration (HideInstance=1), reducing its network visibility.
Versions : 2012-2025
SURF006sa account renamed
InfoChecks that the principal_id=1 account (default 'sa') has been renamed, which hinders name-based brute-force attacks.
Versions : 2012-2025
SURF012Unused Service Broker endpoints
InfoLists Service Broker TCP endpoints that expose the network and should be removed if conversational messaging is unused.
Versions : 2012-2025
TLS012SQL Browser / dynamic ports posture
InfoEvaluates the instance discovery surface: running SQL Browser service and use of dynamic TCP ports.
Versions : 2012-2025
Other categories
- Backups 11
- Reliability 64
- Encryption 14
- Configuration 33
- Maintenance 33
- Performance 29
- Database Settings 13
- Files 10
- Wait Statistics 9
- Advanced I/O 5
- Advanced Memory 8
- Blocking & Deadlocks 8
- Agent 8
- Query Store 8
- Linked Servers 5
- Capacity 9
- Updates 7
- Hardware 10
- Top Queries 7
- Stored Procedures 4
- Connections 6
- Extended Events 4
- Database Mail 3
- Database Level 7